VDB
CISA-2024-5014
CISA-2024-5014
PUBLISHED
CVSS 7.1 HIGH
Reported by ProgressSoftware · Published June 25, 2024
In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any authenticated user to retrieve ASP reports from an HTML form.
Risk Scores
CVSS 3.1
7.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Progress Software Corporation | WhatsUp Gold | 2023.1.0 |
| progress | whatsup_gold | 2023.1.0, 2023.1.0 |
| Progress Software Corporation | WhatsUp Gold | 2023.1.0, 2023.1.0 |
Timeline
- Jun 25, 2024 CVE Published
- Aug 1, 2024 CVE Updated